Junglewise Threat Intelligence

CVE-2026-88340: YARA invalid pointer release in .yrc deserialization

CVE-2026-88340 · Severity: high · CVSS 7.6 · Published 2026-09-22

Executive brief

YARA is a pattern matching engine widely used by security teams to detect malware and analyze files. A vulnerability in how YARA reads compiled rule files (.yrc) allows an attacker to craft a malicious file that causes the application to crash or potentially execute arbitrary code through memory corruption. An attacker who can provide a .yrc file to a system running YARA can trigger a denial of service or memory corruption attack.

Technical details

An invalid pointer release vulnerability (CWE-763) exists in YARA 4.5.8's .yrc file deserializer, where external-variable pointers are not validated during load time. Unpatched pointer fields in the external-variable table can be set to arbitrary values by a crafted .yrc file, leading to invalid free in yr_rules_destroy() or wild-pointer dereference in yr_object_create() when the rules are used. The vulnerability is reachable via the public API (yr_rules_load_stream) and the command-line interface.

Affected products

  • VirusTotal YARA 4.5.8

Timeline

  • 2026-08-07: disclosed: Vulnerability reported on GitHub issue #2239
  • 2026-09-22: advisory: CVE-2026-88340 published
  • 2026-08-25: patched: Fix proposed in pull request #2244

References

Related threats